hardMultiple Choice
AIF-C01 Practice Question: A security team needs to detect anomalies in AWS…
A security team needs to detect anomalies in AWS CloudTrail logs to identify potential unauthorized access. They want to use machine learning without manually labeling data or training custom models. Which AWS service should they use?
⚠ Common exam trap
Watch out — candidates often confuse Amazon GuardDuty with Amazon Detective, assuming Detective performs the initial anomaly detection, when in fact Detective is a post-incident investigation tool that consumes findings from GuardDuty and other sources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon GuardDuty
Amazon GuardDuty is a threat detection service that uses machine learning and anomaly detection to continuously monitor AWS CloudTrail logs, VPC Flow Logs, and DNS logs for unauthorized access and malicious activity. It requires no manual labeling of data or custom model training, as it leverages pre-built ML models and integrated threat intelligence to identify suspicious behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Macie
Why it's wrong here
Macie uses machine learning to discover and classify sensitive data in Amazon S3, so it never inspects CloudTrail API activity for unauthorised access. It is tempting because it is an ML-powered security service requiring no labelling, but its data-perimeter scope addresses S3 content, whereas the scenario concerns CloudTrail log anomalies.
- ✗
Amazon SageMaker
Why it's wrong here
SageMaker requires you to build, train and tune models yourself, so it cannot deliver anomaly detection without labelled data or custom training. It is tempting because SageMaker hosts ready-made algorithms, but those still need configuration and training; the scenario demands a pre-trained service such as Amazon GuardDuty.
- ✓
Amazon GuardDuty
Why this is correct
Amazon GuardDuty continuously analyses CloudTrail management and data events, VPC flow logs and DNS logs using AWS-managed threat intelligence and anomaly detection, raising findings without any labelling or model training by the security team, satisfying the no-custom-model constraint.
- ✗
Amazon Detective
Why it's wrong here
Detective correlates CloudTrail, VPC flow and GuardDuty findings into behaviour graphs for human investigation, but it does not itself apply machine learning to flag anomalies without labelled data or model training. It is tempting as a security analytics tool, yet its purpose is post-detection triage, not unsupervised anomaly detection.
Go deeper
Related to this question
About these practice questions
This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.